This page aggregates publicly disclosed CVE and security risk information related to chxo, with CVSS, EPSS, publication dates, and vulnerability intelligence data to help assess potential risk and remediation priority.
| CVE | 概要 | ソース | CVSS 最大値 | EPSS(%) | 公開 | 更新 |
|---|---|---|---|---|---|---|
| CVE-2006-4552 | Cross-site scripting (XSS) vulnerability in CHXO Feedsplitter 2006-01-21 allows remote attackers to inject arbitrary web script or HTML via the RSS feed. | [email protected] | 6.8 | 1.24% | 2006-09-05 | 2026-06-16 |
| CVE-2006-4551 | Eval injection vulnerability in CHXO Feedsplitter 2006-01-21 allows remote attackers to execute arbitrary PHP code via (1) the file specified as the value of the format parameter, and possibly (2) the RSS feed. | [email protected] | 7.5 | 1.47% | 2006-09-05 | 2026-06-16 |
| CVE-2006-4550 | Directory traversal vulnerability in CHXO Feedsplitter 2006-01-21 allows remote attackers to read arbitrary XML files via .. (dot dot) sequences in the format parameter with a leading ".", which bypasses a security check. | [email protected] | 5.0 | 1.63% | 2006-09-05 | 2026-06-16 |
| CVE-2006-4549 | CHXO Feedsplitter 2006-01-21 allows remote attackers to read the source code of feedsplitter.php via the showsource function. NOTE: this issue is not a vulnerability in standard distributions, but could be an issue if the source has been modified. | [email protected] | 5.0 | 1.32% | 2006-09-05 | 2026-06-16 |